Wednesday, March 2, 2016

[USN-2916-1] Perl vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJW1vRoAAoJEGVp2FWnRL6Tqo4P/AyFIjipD1KkuVH+HNcRlKet
4Q8sda+FS+WcXcH1RXMO9AUYntLLapNPlPo3wQ9Nrd7+AcPwEJ4ieNCy1k+QfZI1
3CEITtFmVrewwFeLQEA26jlnC62bUNfMM8wPcbJWRmUxyO/L6AdoOGO7G7B7kgaK
yoC8cJdtppaJM56w67WrcZXsp73BXIa66GrrsMNxFP5FQwQAClWtMEt+dT3+2nmy
sj3RdqF0VTqEbLm4gv3rGEVZtvOG7g7h3B6NvG0HVapsHO76wunPLtcAvLlRko61
NtRFoqhi4YzswrrwZx1ME4wI/aQKjs9gupn/6B7oCuiSK9bV6gM1mIaT8RBuSgBk
llzvsSDD8wGUMBX+yc+uxNnDObMc6Efep/wV7nXgC0UL7RULB5MI4rnIRcZNUuOL
lWKjp/XR8VqB6hnAXpOZGY4VyM+RXHW+6CeZyg5Xlsf59BWldhpqsjoaV1KnVz1k
kiOdeLPJI+QDg+lrofoMG9V3uUg1Krcuvk9bEJ6EOtTIkMW+o7gIa3436xBHPO7T
Z+OeSmX+paiPmVSqWFUvSpbrNsQqKXQiyckkJ66j6pC6MMBzayDX0+cArwDNfsw9
qa1VjYkrGstDnpFaj1bTkGsVVYL4JoLyqi4g6ed+fkV/Z0tL//9uXUOOjtP9qkoR
gAGW6HVbSWQfxex8+ddI
=p/iX
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2916-1
March 02, 2016

perl vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in Perl.

Software Description:
- perl: Practical Extraction and Report Language

Details:

It was discovered that Perl incorrectly handled certain regular expressions
with an invalid backreference. An attacker could use this issue to cause
Perl to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2013-7422)

Markus Vervier discovered that Perl incorrectly handled nesting in the
Data::Dumper module. An attacker could use this issue to cause Perl to
consume memory and crash, resulting in a denial of service. (CVE-2014-4330)

Stephane Chazelas discovered that Perl incorrectly handled duplicate
environment variables. An attacker could possibly use this issue to bypass
the taint protection mechanism. (CVE-2016-2381)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
perl 5.20.2-6ubuntu0.2

Ubuntu 14.04 LTS:
perl 5.18.2-2ubuntu1.1

Ubuntu 12.04 LTS:
perl 5.14.2-6ubuntu2.5

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2916-1
CVE-2013-7422, CVE-2014-4330, CVE-2016-2381

Package Information:
https://launchpad.net/ubuntu/+source/perl/5.20.2-6ubuntu0.2
https://launchpad.net/ubuntu/+source/perl/5.18.2-2ubuntu1.1
https://launchpad.net/ubuntu/+source/perl/5.14.2-6ubuntu2.5

Tuesday, March 1, 2016

[announce] NYC*BUG Wednesday: BSD init(8) and rc(8)

March 2, Wednesday
BSD init(8) and rc(8): Room for Improvement?, Raul Cuza
18:45, Stone Creek Bar & Lounge: 140 E 27th St

Abstract

The current init(1) and rc(1) startup services have served BSD well for
many years. But are they long in the tooth?

There are a host of problems that it does not solve. This begs the
question of whether it is time to replace it with something better. More
importantly what could be better? This talk will look at the existing
initialization and coordination system that currently serves the major
BSD projects, what problems they solve and what problems they do not
solve. We will review alternatives and how their approaches will impact
how we work. Some of the alternatives that will be discussed include
relaunchd, nosh, and systemd.

Speaker Bio

Raul Cuza makes pretenses to being a modern hip SysAdmin, but can't
forget late nights installing Sun-3s to pull it off successfully.

He has spent most of his career in K-12 schools reminding Cupertino-
designed hardware that there is BSD somewhere under all the glitz. Many
years making OpenBSD firewalls to replace web ads with student artwork
and keeping OS X machines useful tools for learning has taught him that
the real impact of the computer age does not happen in the server room
but couldn't happen without it either.

He is currently challenged with getting meaningful work done on other
people's hardware residing in other people's server rooms distributed
around the globe. He has permission to use them.

_______________________________________________
announce mailing list
announce@lists.nycbug.org
http://lists.nycbug.org/mailman/listinfo/announce

[USN-2915-1] Django vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJW1eXJAAoJEGVp2FWnRL6TtBgP/R8rfJO2pSNvH+0JCRq83bMi
sGDXj81kieVsM+mADjKTBIGa0/NQ7oPDsCoRGxh2SIO79C4YHVQqwnZ0E1uu0yh5
lFuBdMYgSrlErW70tKBwwO7bUJxq/4179eVNsK06bRlt48RTEz6QHBVtxDbjkzoB
IpAPySiSoYb9RrNHF5FfF7Wf729Bt7swtXk5gFJ3I114jMsYuVeejnxoP4hhEH1F
Fq/IHj895/u/csFWF/A4uOmduBZ68CB/hYd9NBixoQx6RPZZ14P0qlW1z3ldKeLE
YyZAVh47cDbAKRkEbwTcazyxrYXGL8KWeKeAoFh7N/rx4cM+4iju6xyJn+1IfR53
fCe6v/p4MiDXdV/qukeJ/5bWqLjYreC4HHebXcQsvikKfm5yJmJQb5UhnPTqsibn
Az37LdZ0we39tfDHeRnOP2zRWvBDLVsEeEXTUQboOs+WgAXdfZGkPLg1NOLi6Del
jsZpJsTcIISDm9Qc1L1xslPVx0oYSuhxKPV+QFvJbKgZbgFeTDZ6iD6zRRdOT465
Cy1cxkhWfcOkPwAG55iKX6pquESEghfWUAEjQzuKUpig6KNSiTJO08UYPw+QPaom
Ec0j054cLazf7MvSlmdWfH4ECbSbZfFQYcGW7CpnRhPzXCK+9pduR7UpSQSXdzgD
hums16foRRsC+/HJMWmT
=dj4e
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2915-1
March 01, 2016

python-django vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in Django.

Software Description:
- python-django: High-level Python web development framework

Details:

Mark Striemer discovered that Django incorrectly handled user-supplied
redirect URLs containing basic authentication credentials. A remote
attacker could possibly use this issue to perform a cross-site scripting
attack or a malicious redirect. (CVE-2016-2512)

Sjoerd Job Postmus discovered that Django incorrectly handled timing when
doing password hashing operations. A remote attacker could possibly use
this issue to perform user enumeration. (CVE-2016-2513)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
python-django 1.7.9-1ubuntu5.2
python3-django 1.7.9-1ubuntu5.2

Ubuntu 14.04 LTS:
python-django 1.6.1-2ubuntu0.12

Ubuntu 12.04 LTS:
python-django 1.3.1-4ubuntu1.20

In general, a standard system update will make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2915-1
CVE-2016-2512, CVE-2016-2513

Package Information:
https://launchpad.net/ubuntu/+source/python-django/1.7.9-1ubuntu5.2
https://launchpad.net/ubuntu/+source/python-django/1.6.1-2ubuntu0.12
https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.20

[CentOS-announce] CESA-2016:0302 Important CentOS 5 openssl Security Update

CentOS Errata and Security Advisory 2016:0302 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-0302.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
045550a5b7552b7a9cd5ea7a1f866de367e3bf677d240925d633a1b7938cd07a openssl-0.9.8e-39.el5_11.i386.rpm
8c73a864ce991ba4e6c950cc6ca642c09a7753fc5aa793a0a23e683ba5df99e9 openssl-0.9.8e-39.el5_11.i686.rpm
230b07861835e3a65052e45b617a73cbbd3057c6db38d315dbed7b3d01f1fba6 openssl-devel-0.9.8e-39.el5_11.i386.rpm
c63d611b4519928413ed611a020d7e7113ccbf6890b264b4b8399f9af7bf6140 openssl-perl-0.9.8e-39.el5_11.i386.rpm

x86_64:
8c73a864ce991ba4e6c950cc6ca642c09a7753fc5aa793a0a23e683ba5df99e9 openssl-0.9.8e-39.el5_11.i686.rpm
d7e159cfd9e991adf152df48cb97751c8a26601b1f3f3a70a3e137efb05e0c35 openssl-0.9.8e-39.el5_11.x86_64.rpm
230b07861835e3a65052e45b617a73cbbd3057c6db38d315dbed7b3d01f1fba6 openssl-devel-0.9.8e-39.el5_11.i386.rpm
f6bc29a1ab08303174206210af09b37ec53f0c0d643f18bf98427b20f2cb4a67 openssl-devel-0.9.8e-39.el5_11.x86_64.rpm
7953dcc480ff7815f39943f62fc848b3ce7ecb66217d2829332d95be4400c13d openssl-perl-0.9.8e-39.el5_11.x86_64.rpm

Source:
e0dab71e400c340b8eed7770c582ce6f3768888a61b4c492411d20e81ae1a9a6 openssl-0.9.8e-39.el5_11.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:0301 Important CentOS 7 openssl Security Update

CentOS Errata and Security Advisory 2016:0301 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-0301.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

x86_64:
b2aaed03ed2d01d2a6482ed97a95aec0545ffc4c00ad46c7cafc10c9554e1b58 openssl-1.0.1e-51.el7_2.4.x86_64.rpm
b1aa349c2ea3a99cc65d031850d415b7feb7924f0a121593c12b439934440eb4 openssl-devel-1.0.1e-51.el7_2.4.i686.rpm
3e194452a2616702ee91e791b163b739d012da52957f6e91927de9d554e4e203 openssl-devel-1.0.1e-51.el7_2.4.x86_64.rpm
2e193ea886626e3e8b151f905920503e2e505cc2bdfef31a8d38a581c99e210f openssl-libs-1.0.1e-51.el7_2.4.i686.rpm
249cc7d68c0d8d48a26b50066ed29da2d70c7a573d23dc566ee7c99f5c5f71c9 openssl-libs-1.0.1e-51.el7_2.4.x86_64.rpm
61cfe9edcb1d521b2978fee1acda2a9cba73f2c371bc9217b44bd527569938c5 openssl-perl-1.0.1e-51.el7_2.4.x86_64.rpm
a5d2395db7a0c87d069e3fc80e55deacffeea5acc5162058075a746871954ce7 openssl-static-1.0.1e-51.el7_2.4.i686.rpm
e48dd73a4f9bc7d3b6617842414a1b50fc086c720795451ca4795ecd08ba3b22 openssl-static-1.0.1e-51.el7_2.4.x86_64.rpm

Source:
26fa86503898fa5fcf91188aa6f56172ea1896e4d4943bd407aa54d21d330618 openssl-1.0.1e-51.el7_2.4.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

[CentOS-announce] CESA-2016:0301 Important CentOS 6 openssl Security Update

CentOS Errata and Security Advisory 2016:0301 Important

Upstream details at : https://rhn.redhat.com/errata/RHSA-2016-0301.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
31cacdfe88b5e4b420bd2dd1fe6b491b35a2a57c7e3b4ef5b960573b095fc519 openssl-1.0.1e-42.el6_7.4.i686.rpm
a57701c0598a7c91de1eac55fa5b6ffe2bc096c07f757723d6de65dd092dbc66 openssl-devel-1.0.1e-42.el6_7.4.i686.rpm
3e62aef02b5a465d587a3c3dfec494b27d55ec2a5dac0a13e6ac842188728d66 openssl-perl-1.0.1e-42.el6_7.4.i686.rpm
621cd98e6d221febb477906443a1692afd64ffcc79cb843a146ee4583e7224f7 openssl-static-1.0.1e-42.el6_7.4.i686.rpm

x86_64:
31cacdfe88b5e4b420bd2dd1fe6b491b35a2a57c7e3b4ef5b960573b095fc519 openssl-1.0.1e-42.el6_7.4.i686.rpm
e5fc87d5031ea23db0eb2be92743a557d8574caa583fad6a1cd16a757ed436f3 openssl-1.0.1e-42.el6_7.4.x86_64.rpm
a57701c0598a7c91de1eac55fa5b6ffe2bc096c07f757723d6de65dd092dbc66 openssl-devel-1.0.1e-42.el6_7.4.i686.rpm
17b6a4dbe2f844d3944fa7c4cafe9ccf4d54a8dc23d26201a513fc86bd08d256 openssl-devel-1.0.1e-42.el6_7.4.x86_64.rpm
4b9ec40e680ad72d6134283f3ab6179d2c4c8a34433aed4f42c5117bfeb300a5 openssl-perl-1.0.1e-42.el6_7.4.x86_64.rpm
aaaf4d42ef5f48f424ed9d6d04744e906a15d3ae66097bcd3ec60be226879cd6 openssl-static-1.0.1e-42.el6_7.4.x86_64.rpm

Source:
152d1ec6f40854680bbad1524f2b7766c8f583de6b1a136b635ec9b257d4b088 openssl-1.0.1e-42.el6_7.4.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

reallost1.fbsd2233449

   朋友、您有投资股票吗? 您有亏过钱吗?您想赚回亏掉的损失吗?
我们不能保证您赚钱,但是我们绝对可以帮您
规避风险,让您在股市中顶点逃离、低点操盘、
稳操胜券。
   免费听课好股推荐:妙法解套、每天超过12小
时专业老师股票指导。支持手机APP  直播间在线
讲解。
                   咨  询  Q Q:369074186
                   免费报名电话:020-38575582

[USN-2914-1] OpenSSL vulnerabilities

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJW1bFLAAoJEGVp2FWnRL6TUNEP/RuXrx21u17g0tElmSjC/OM5
rg5pJUYRCVyMdWX1GyEkJeYKOpsiGLapywC3jh85jCHAOxj9uN/3ZAW/U7ILXb+w
QhADIaNNWTunWY+8r9t2t9o9E73r3rPNvBZRKz8Zc/brLskOh6mLAR+lD+TDCNNj
ERpQ8GZajBzN/gJrbW9l2owMnCeflqrbQqKIejA23D95nZgdRTSGHzKEZYUvgq7I
DPk/Ny1bhZ4Av7XG/7fWqTBtgakzK0O6ozoiW4OwkTO8Q1WfO7moKV/3W6jWt54Y
438sFz4dtDjFsfdBSlXdMdaHXRuGtcwiugcUL08LPCLV2oW/8s2KUeEBJxw7UZLm
Gzy9yi+trnh50symaaB16Kd9VACk68H+XC2dARLFTllJgb2U3Es41lG2PLocHwAo
VXGML8cltoGQ2yvlSRdy2qp9YZCnUC9qxcaiWH1toyZjn1NkKXmCKNuewzouuImn
vA7jWZtKKLn+q0Znr0vPha6czbNSa0fnW1hCEsaFYzvv6d/CHB2zQDjYTX4iWLEE
8K77s42FE+8ol4bSCIWCR601DGcmcvdUi1AfcC5u9Z70kfMpGIlT/+IIkBAXE8rH
f8lcEKBL6L8jLhxuBlMqpBFUXeLfrw22DBkgDDy5mgUhXzNPf2u9kjsHpswIjx/t
bewonxmNe+1NibibSzIM
=Qsi/
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-2914-1
March 01, 2016

openssl vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 15.10
- Ubuntu 14.04 LTS
- Ubuntu 12.04 LTS

Summary:

Several security issues were fixed in OpenSSL.

Software Description:
- openssl: Secure Socket Layer (SSL) cryptographic library and tools

Details:

Yuval Yarom, Daniel Genkin, and Nadia Heninger discovered that OpenSSL was
vulnerable to a side-channel attack on modular exponentiation. On certain
CPUs, a local attacker could possibly use this issue to recover RSA keys.
This flaw is known as CacheBleed. (CVE-2016-0702)

Adam Langley discovered that OpenSSL incorrectly handled memory when
parsing DSA private keys. A remote attacker could use this issue to cause
OpenSSL to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-0705)

Guido Vranken discovered that OpenSSL incorrectly handled hex digit
calculation in the BN_hex2bn function. A remote attacker could use this
issue to cause OpenSSL to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2016-0797)

Emilia Käsper discovered that OpenSSL incorrectly handled memory when
performing SRP user database lookups. A remote attacker could possibly use
this issue to cause OpenSSL to consume memory, resulting in a denial of
service. (CVE-2016-0798)

Guido Vranken discovered that OpenSSL incorrectly handled memory when
printing very long strings. A remote attacker could use this issue to cause
OpenSSL to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-0799)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
libssl1.0.0 1.0.2d-0ubuntu1.4

Ubuntu 14.04 LTS:
libssl1.0.0 1.0.1f-1ubuntu2.18

Ubuntu 12.04 LTS:
libssl1.0.0 1.0.1-4ubuntu5.35

After a standard system update you need to reboot your computer to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2914-1
CVE-2016-0702, CVE-2016-0705, CVE-2016-0797, CVE-2016-0798,
CVE-2016-0799

Package Information:
https://launchpad.net/ubuntu/+source/openssl/1.0.2d-0ubuntu1.4
https://launchpad.net/ubuntu/+source/openssl/1.0.1f-1ubuntu2.18
https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.35

[CentOS-announce] CEBA-2016:0298 CentOS 6 findutils FASTTRACK BugFix Update

CentOS Errata and Bugfix Advisory 2016:0298

Upstream details at : https://rhn.redhat.com/errata/RHBA-2016-0298.html

The following updated files have been uploaded and are currently
syncing to the mirrors: ( sha256sum Filename )

i386:
ed1a7580800b4cb68fd882f39eafe9c4a0d8b2ec9ff6d25358f2f10d9cc35555 findutils-4.4.2-9.el6.i686.rpm

x86_64:
fbbb4d9e91b0a7cac328167d09a3591d9ee50e990d86da45bee99f8020a03db3 findutils-4.4.2-9.el6.x86_64.rpm

Source:
8f0afaba4a8461e71ea4001750df754ff6406e5a68e5276c8aae4a36a6a9632c findutils-4.4.2-9.el6.src.rpm



--
Johnny Hughes
CentOS Project { http://www.centos.org/ }
irc: hughesjr, #centos@irc.freenode.net
Twitter: @JohnnyCentOS

_______________________________________________
CentOS-announce mailing list
CentOS-announce@centos.org
https://lists.centos.org/mailman/listinfo/centos-announce

lists.linuxfromscratch.org mailing list memberships reminder

This is a reminder, sent out once a month, about your
lists.linuxfromscratch.org mailing list memberships. It includes your
subscription info and how to use it to change it or unsubscribe from a
list.

You can visit the URLs to change your membership status or
configuration, including unsubscribing, setting digest-style delivery
or disabling delivery altogether (e.g., for a vacation), and so on.

In addition to the URL interfaces, you can also use email to make such
changes. For more info, send a message to the '-request' address of
the list (for example, mailman-request@lists.linuxfromscratch.org)
containing just the word 'help' in the message body, and an email
message will be sent to you with instructions.

If you have questions, problems, comments, etc, send them to
mailman-owner@lists.linuxfromscratch.org. Thanks!

Passwords for reallost1.fbsd2233449@blogger.com:

List Password // URL
---- --------
lfs-announce@lists.linuxfromscratch.org vaozebru
http://lists.linuxfromscratch.org/options/lfs-announce/reallost1.fbsd2233449%40blogger.com

reallost1.fbsd2233449

   朋友、您有投资股票吗? 您有亏过钱吗?您想赚回亏掉的损失吗?
我们不能保证您赚钱,但是我们绝对可以帮您
规避风险,让您在股市中顶点逃离、低点操盘、
稳操胜券。
   免费听课好股推荐:妙法解套、每天超过12小
时专业老师股票指导。支持手机APP  直播间在线
讲解。
                   咨  询  Q Q:369074186
                   免费报名电话:020-38575582

reallost1.fbsd2233449:如何成为职业助理

reallost1.fbsd2233449:您好

在竞争日益激烈的今天,唯有提升自我的能力,才能不被别人所取代!

附件中的内容希望能帮助到您的工作,给您解决工作中的烦恼!

nmbdz

2016-3-117:47:33